5
    Medium

    CVE-2002-1101

    Last Modified: 7 Oct 2012

    Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.

    Source:Phenoelit
    Published:10 Sept 2002
    5
    Medium

    CVE-2002-1089

    Last Modified: 1 Oct 2012

    rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which could enable remote attackers to use the information in additional attacks.

    Source:skp
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1079

    Last Modified: 4 Oct 2012

    Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

    Source:Auriemma Luigi
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-1077

    Last Modified: 2 Oct 2012

    IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length field.

    Source:anonymous
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1076

    Last Modified: 1 Oct 2012

    Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0.

    Source:anonymous
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-1075

    Last Modified: 8 Oct 2012

    Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) To or (2) From headers.

    Source:Auriemma Luigi
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1073

    Last Modified: 6 Sept 2016

    Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a long password.

    Source:anonymous
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1072

    Last Modified: 1 Oct 2012

    ZyXEL Prestige 642R 2.50(FA.1) and Prestige 310 V3.25(M.01), allows remote attackers to cause a denial of service via an oversized, fragmented "jolt" style ICMP packet.

    Source:Jeff w. Roberson
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1071

    Last Modified: 27 Sept 2012

    ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) via a TCP packet with both the SYN and ACK flags set.

    Source:Kistler Ueli
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1070

    Last Modified: 30 Sept 2012

    Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PHPWiki users via the pagename parameter.

    Source:Pistone
    Published:31 Aug 2002
    4.3
    Medium

    CVE-2002-1060

    Last Modified: 1 Oct 2012

    Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06, Security Gateway 2.1.02, and Server Accelerator 4.1.06 allows remote attackers to inject arbitrary web script or HTML via a URL to a nonexistent hostname that includes the HTML, which is inserted into the resulting error page.

    Source:T.Suzuki
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-1059

    Last Modified: 1 Oct 2012

    Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execute arbitrary code via a long SSH1 protocol version string.

    Source:Kyuzo
    Published:4 Oct 2002
    10
    Critical

    CVE-2002-1058

    Last Modified: 1 Oct 2012

    Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gain privileges as the Qube Admin via .. (dot dot) sequences in the sessionId cookie that point to an alternate session file.

    Source:pokley
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1057

    Last Modified: 1 Oct 2012

    Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a long USER command.

    Source:anonymous
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-1048

    Last Modified: 28 Oct 2012

    HP JetDirect printers allow remote attackers to obtain the administrative password for the (1) web and (2) telnet services via an SNMP request to the variable (.iso.3.6.1.4.1.11.2.3.9.4.2.1.3.9.1.1.0.

    Source:Sven Pechler
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1043

    Last Modified: 8 Oct 2012

    Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").

    Source:Auriemma Luigi
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1042

    Last Modified: 29 Sept 2012

    Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise Server 3.6, when running on Windows platforms, allows remote attackers to read arbitrary files via ..\ (dot-dot backslash) sequences in the NS-query-pat parameter.

    Source:Qualys Corporation
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1036

    Last Modified: 30 Sept 2012

    Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote attackers to execute web script via the (1) Rank or (2) Match parameters.

    Source:VALDEUX
    Published:31 Aug 2002
    10
    Critical

    CVE-2002-1034

    Last Modified: 30 Sept 2012

    none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argument.

    Source:JWC
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1033

    Last Modified: 30 Sept 2012

    Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via a "..:" sequence (dot-dot variant) in the argument.

    Source:JWC
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1031

    Last Modified: 29 Sept 2012

    KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request containing a %00 (null) character.

    Source:Securiteinfo.com
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-1029

    Last Modified: 29 Sept 2012

    Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malformed request to TCP port 17990.

    Source:altomo
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1028

    Last Modified: 30 Sept 2012

    Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cause a denial of service (crash) via long arguments.

    Source:Lucas Lundgren
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1027

    Last Modified: 30 Sept 2012

    Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (277.1) allows remote attackers to execute arbitrary web script via a link to 500error.jsp with the script in 1the et parameter.

    Source:Peter Gründl
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1023

    Last Modified: 29 Sept 2016

    BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.

    Source:Matthew Murphy
    Published:31 Aug 2002
    5
    Medium

    CVE-2002-1021

    Last Modified: 30 Sept 2012

    BadBlue server allows remote attackers to read restricted files, such as EXT.INI, via an HTTP request that contains a hex-encoded null byte.

    Source:Matthew Murphy
    Published:31 Aug 2002
    4.6
    Medium

    CVE-2002-1016

    Last Modified: 1 Oct 2012

    Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key data files, performing the operations, and restoring the original data files.

    Source:Vladimir Katalov
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1014

    Last Modified: 30 Sept 2012

    Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image.

    Source:UNYUN
    Published:4 Oct 2002
    7.2
    High

    CVE-2002-1013

    Last Modified: 28 Sept 2012

    Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Media-IXT 3.0.4 allows local users to gain root privileges via a long -path argument.

    Source:Juliano Rizzo
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-1009

    Last Modified: 30 Sept 2012

    Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via the (1) "Name" or (2) "E-mail" parameters.

    Source:Matthew Murphy
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1008

    Last Modified: 28 Sept 2012

    Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attackers to execute arbitrary web script in other web browsers via a request to urlcount.cgi that contains the script, which is not filtered when the REPORT capability prints the original request.

    Source:Matthew Murphy
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-1007

    Last Modified: 29 Sept 2012

    Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the course_id parameter in a link to login.pl, (2) the CTID parameter in ProcessInfo.cgi, or (3) the Message parameter in index.cgi.

    Source:Berend-Jan Wever
    Published:31 Aug 2002
    6.8
    Medium

    CVE-2002-1006

    Last Modified: 29 Sept 2012

    Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier allows remote attackers to execute arbitrary web script via parserl.pl.

    Source:Mark Rowe
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-1004

    Last Modified: 29 Sept 2012

    Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remote attackers to read arbitrary files via .. (dot dot) sequences in a URL.

    Source:team n.finity
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-1001

    Last Modified: 29 Sept 2012

    Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long HTTP request to TCP port 6588 or (2) a SOCKS 4A request to TCP port 1080 with a long DNS hostname.

    Source:Kanatoko
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0995

    Last Modified: 29 Sept 2012

    login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action parameter set to "insert," which adds the provided username to the adminUsers table.

    Source:ethx
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-0994

    Last Modified: 29 Sept 2012

    SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.

    Source:Richard van den Berg
    Published:31 Aug 2002
    7.2
    High

    CVE-2002-0991

    Last Modified: 28 Sept 2012

    Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, allows local users to gain root privileges via long (1) -U, (2) -D, (3) -P, (4) -S, (5) -N, or (6) -u parameters.

    Source:watercloud
    Published:31 Aug 2002
    7.2
    High

    CVE-2002-0987

    Last Modified: 6 Oct 2012

    X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp using popen, which could allow local users to gain privileges.

    Source:Olaf Kirch
    Published:24 Sept 2002
    7.5
    High

    CVE-2002-0982

    Last Modified: 1 Oct 2012

    Microsoft SQL Server 2000 SP2, when configured as a distributor, allows attackers to execute arbitrary code via the @scriptfile parameter to the sp_MScopyscript stored procedure.

    Source:Cesar Cerrudo
    Published:23 Aug 2002
    7.5
    High

    CVE-2002-0980

    Last Modified: 3 Oct 2012

    The Web Folder component for Internet Explorer 5.5 and 6.0 writes an error message to a known location in the temporary folder, which allows remote attackers to execute arbitrary code by injecting it into the error message, then referring to the error message file via a mhtml: URL.

    Source:http-equiv
    Published:23 Aug 2002
    6.4
    Medium

    CVE-2002-0976

    Last Modified: 4 Oct 2012

    Internet Explorer 4.0 and later allows remote attackers to read arbitrary files via a web page that accesses a legacy XML Datasource applet (com.ms.xml.dso.XMLDSO.class) and modifies the base URL to point to the local system, which is trusted by the applet.

    Source:Jelmer
    Published:23 Aug 2002
    5
    Medium

    CVE-2002-0974

    Last Modified: 4 Oct 2012

    Help and Support Center for Windows XP allows remote attackers to delete arbitrary files via a link to the hcp: protocol that accesses uplddrvinfo.htm.

    Source:Shane Hird
    Published:24 Sept 2002
    7.5
    High

    CVE-2002-0968

    Last Modified: 28 Sept 2012

    Buffer overflow in AnalogX SimpleServer:WWW 1.16 and earlier allows remote attackers to cause a denial of service (crash) and execute code via a long HTTP request method name.

    Source:Auriemma Luigi
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-0965

    Last Modified: 7 Mar 2011

    Buffer overflow in TNS Listener for Oracle 9i Database Server on Windows systems, and Oracle 8 on VM, allows local users to execute arbitrary code via a long SERVICE_NAME parameter, which is not properly handled when writing an error message to a log file.

    Source:Metasploit
    Published:4 Oct 2002
    5
    Medium

    CVE-2002-0964

    Last Modified: 1 Oct 2012

    Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via multiple responses to the initial challenge with different cd_key values, which reaches the player limit and prevents other players from connecting until the original responses have timed out.

    Source:Auriemma Luigi
    Published:4 Oct 2002
    7.5
    High

    CVE-2002-0962

    Last Modified: 26 Sept 2012

    Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, (2) the topic parameter in index.php, or (3) the title parameter in comment.php.

    Source:Ahmet Sabri ALPER
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0961

    Last Modified: 24 Sept 2012

    Vulnerabilities in Voxel Dot Net CBMS 0.7 and earlier allow remote attackers to conduct unauthorized operations as other users, e.g. by deleting clients via dltclnt.php, possibly in a SQL injection attack.

    Source:Ulf Harnhammar
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0959

    Last Modified: 24 Sept 2012

    Cross-site scripting vulnerability in Splatt Forum 3.0 allows remote attackers to execute arbitrary script as other users via an [img] tag with a closing quote followed by the script.

    Source:MegaHz
    Published:31 Aug 2002
    7.5
    High

    CVE-2002-0955

    Last Modified: 28 Sept 2012

    Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remote attackers to execute arbitrary script as other web site visitors via script in the num parameter, which is not filtered in the resulting error message.

    Source:methodic
    Published:31 Aug 2002